US11157366B1ActiveUtility

Securing data in a dispersed storage network

Assignee: PURE STORAGE INCPriority: Jul 31, 2015Filed: Aug 29, 2019Granted: Oct 26, 2021
Est. expiryJul 31, 2035(~9 yrs left)· nominal 20-yr term from priority
Inventors:Jason K. Resch
H04L 67/1097H04L 67/63G06F 13/4282G06F 3/064H03M 13/2906G06F 3/0619H04L 63/0428G06F 21/645G06F 3/0644G06F 16/24578G06F 11/108G06F 16/1824G06F 3/061G06F 3/065G06F 21/6218H04L 9/0861H03M 13/1515H03M 13/3761G06F 3/0653H04L 63/0853G06F 11/1076G06F 3/0643G06F 3/0668H04L 63/108G06F 3/067G06F 3/0689G06F 2201/805G06F 16/122G06F 11/1662G06F 3/0647H04L 63/061G06F 3/0605G06F 3/0604G06F 3/0622G06F 11/3034H04L 67/327
82
PatentIndex Score
1
Cited by
102
References
20
Claims

Abstract

A first encoded data slice is received for storage by a DST execution unit from a first vault. A first encryption key corresponding to the first encoded data slice is generated, and a first encrypted data slice is generated by utilizing the first encryption key. A second encoded data slice for second storage by the DST execution unit from a second vault, a second encryption key corresponding the second encoded data slice is generated, and a second encrypted data slice is generated by utilizing the second encryption key. The first encrypted data slice and the second encrypted data slice are stored in a file of a memory of the DST execution unit, where the file and the memory are common to the first encrypted data slice and the second encrypted data slice.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
       1. A method for execution by a dispersed storage and task (DST) execution unit that includes a processor, the method comprising:
 receiving a first encoded data slice for storage by the DST execution unit, wherein a slice identifier associated with the first encoded data slice indicates a first vault; 
 generating a first encryption key corresponding to the first encoded data slice by performing a deterministic function on a first vault identifier associated with the first vault and a memory identifier associated with one of a plurality of memory devices of the DST execution unit; 
 generating a first encrypted data slice using the first encryption key; 
 storing the first encrypted data slice in a file of the one of the plurality of memory devices of the DST execution unit; 
 receiving a request to retrieve the first encoded data slice; 
 retrieving the first encrypted data slice corresponding to the first encoded data slice from the one of the plurality of memory devices; 
 generating a first decryption key corresponding to the first encoded data slice by performing a second deterministic function on the first vault identifier and the memory identifier, wherein the first decryption key is different from the first encryption key; and 
 regenerating the first encoded data slice using the first decryption key. 
 
     
     
       2. The method of  claim 1 , further comprising:
 receiving a second encoded data slice for storage by the DST execution unit, wherein a slice identifier associated with the second encoded data slice indicates a second vault; 
 generating a second encryption key corresponding the second encoded data slice by performing the deterministic function on a second vault identifier associated with the second vault and the memory identifier; 
 generating a second encrypted data slice using the second encryption key; and 
 storing the second encrypted data slice in the file of the one of the plurality of memory devices of the DST execution unit. 
 
     
     
       3. The method of  claim 2 , further comprising:
 receiving a third encoded data slice for storage by the DST execution unit, wherein a slice identifier associated with the first encoded data slice indicates the first vault; 
 generating a third encrypted data slice by utilizing the first encryption key; and 
 storing the third encrypted data slice and the file of the one of the plurality of memory devices of the DST execution unit. 
 
     
     
       4. The method of  claim 3 , wherein the file and the one of the plurality of memory devices are common to the first encrypted data slice, the second encrypted data slice, and the third encrypted data slice. 
     
     
       5. The method of  claim 2 , wherein the first encryption key is generated by performing the deterministic function further on the slice identifier of the first encoded data slice. 
     
     
       6. The method of  claim 2 , wherein the second encryption key is generated by performing the deterministic function further on the slice identifier associated with the second encoded data slice. 
     
     
       7. The method of  claim 1 , further comprising:
 re-encrypting the first encoded data slice with a new encryption key in response a transfer of the first encoded data slice from the one of the plurality of memory devices to another one of the plurality of memory devices. 
 
     
     
       8. A processing system of a dispersed storage and task (DST) execution unit comprises:
 an interface; and 
 processing circuitry, coupled to the interface, configured by operational instructions to perform operations that include:
 receiving a first encoded data slice for storage by the DST execution unit, wherein a slice identifier associated with the first encoded data slice indicates a first vault; 
 generating a first encryption key corresponding to the first encoded data slice by performing a deterministic function on a first vault identifier associated with the first vault and a memory identifier associated with one of a plurality of memory devices of the DST execution unit; 
 generating a first encrypted data slice using the first encryption key; 
 storing the first encrypted data slice in a file of the one of the plurality of memory devices of the DST execution unit; 
 receiving a request to retrieve the first encoded data slice; 
 retrieving the first encrypted data slice corresponding to the first encoded data slice from the one of the plurality of memory devices; 
 generating a first decryption key corresponding to the first encoded data slice by performing a second deterministic function on the first vault identifier and the memory identifier, wherein the first decryption key is different from the first encryption key; and 
 regenerating the first encoded data slice using the first decryption key. 
 
 
     
     
       9. The processing system of  claim 8 , wherein the operations further include:
 receiving a second encoded data slice for storage by the DST execution unit, wherein a slice identifier associated with the second encoded data slice indicates a second vault; 
 generating a second encryption key corresponding the second encoded data slice by performing the deterministic function on a second vault identifier associated with the second vault and the memory identifier; 
 generating a second encrypted data slice using the second encryption key; and 
 storing the second encrypted data slice in the file of the one of the plurality of memory devices of the DST execution unit. 
 
     
     
       10. The processing system of  claim 9 , wherein the operations further include:
 receiving a third encoded data slice for storage by the DST execution unit, wherein a slice identifier associated with the first encoded data slice indicates the first vault; 
 generating a third encrypted data slice by utilizing the first encryption key; and 
 storing the third encrypted data slice and the file of the one of the plurality of memory devices of the DST execution unit. 
 
     
     
       11. The processing system of  claim 10 , wherein the file and the one of the plurality of memory devices are common to the first encrypted data slice, the second encrypted data slice, and the third encrypted data slice. 
     
     
       12. The processing system of  claim 9 , wherein the first encryption key is generated by performing the deterministic function further on the slice identifier of the first encoded data slice. 
     
     
       13. The processing system of  claim 9 , wherein the second encryption key is generated by performing the deterministic function further on the slice identifier associated with the second encoded data slice. 
     
     
       14. The processing system of  claim 8 , wherein the operations further include:
 re-encrypting the first encoded data slice with a new encryption key in response a transfer of the first encoded data slice from the one of the plurality of memory devices to another one of the plurality of memory devices. 
 
     
     
       15. A non-transitory computer readable storage medium comprises:
 at least one memory section that stores operational instructions that, when executed by a processing system of a dispersed storage and task (DST) execution unit that includes a processor, causes the processing system to perform operations including:
 receiving a first encoded data slice for storage by the DST execution unit, wherein a slice identifier associated with the first encoded data slice indicates a first vault; 
 generating a first encryption key corresponding to the first encoded data slice by performing a deterministic function on a first vault identifier associated with the first vault and a memory identifier associated with one of a plurality of memory devices of the DST execution unit; 
 generating a first encrypted data slice using the first encryption key; 
 storing the first encrypted data slice in a file of the one of the plurality of memory devices of the DST execution unit; 
 receiving a request to retrieve the first encoded data slice; 
 retrieving the first encrypted data slice corresponding to the first encoded data slice from the one of the plurality of memory devices; 
 generating a first decryption key corresponding to the first encoded data slice by performing a second deterministic function on the first vault identifier and the memory identifier, wherein the first decryption key is different from the first encryption key; and 
 regenerating the first encoded data slice using the first decryption key. 
 
 
     
     
       16. The non-transitory computer readable storage medium of  claim 15 , wherein the operations further include:
 receiving a second encoded data slice for storage by the DST execution unit, wherein a slice identifier associated with the second encoded data slice indicates a second vault; 
 generating a second encryption key corresponding the second encoded data slice by performing the deterministic function on a second vault identifier associated with the second vault and the memory identifier; 
 generating a second encrypted data slice using the second encryption key; and 
 storing the second encrypted data slice in the file of the one of the plurality of memory devices of the DST execution unit. 
 
     
     
       17. The non-transitory computer readable storage medium of  claim 16 , wherein the operations further include:
 receiving a third encoded data slice for storage by the DST execution unit, wherein a slice identifier associated with the first encoded data slice indicates the first vault; 
 generating a third encrypted data slice by utilizing the first encryption key; and 
 storing the third encrypted data slice and the file of the one of the plurality of memory devices of the DST execution unit. 
 
     
     
       18. The non-transitory computer readable storage medium of  claim 16 , wherein the first encryption key is generated by performing the deterministic function further on the slice identifier of the first encoded data slice. 
     
     
       19. The non-transitory computer readable storage medium of  claim 16 , wherein the second encryption key is generated by performing the deterministic function further on the slice identifier associated with the second encoded data slice. 
     
     
       20. The non-transitory computer readable storage medium of  claim 15 , wherein the operations further include:
 re-encrypting the first encoded data slice with a new encryption key in response a transfer of the first encoded data slice from the one of the plurality of memory devices to another one of the plurality of memory devices.

Join the waitlist — get patent alerts

Track US11157366B1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.